The intelligence community just let something slip that Congress never fully debated.

The price tag is enormous, the sourcing is classified, and the implications stretch far beyond any single agency budget line.

And what the National Security Agency told lawmakers about its AI spending should have every American asking hard questions about who controls this technology and who pays for it.

Billions Behind Closed Doors

The National Security Agency told lawmakers it is spending billions of dollars in taxpayer funds this year evaluating and testing advanced artificial intelligence models, according to two sources familiar with classified intelligence estimates, as reported by the Washington Sun.

No public budget document has confirmed the total. The Pentagon has not commented on how NSA resources are being allocated. The entire claim rests on anonymous sourcing from people with access to classified figures.

That alone should give pause.

The NSA’s Artificial Intelligence Security Center has been running these frontier model tests specifically to identify potential national security vulnerabilities. Frontier models are the most capable AI systems currently available from companies like Anthropic, OpenAI, and Google. These are systems sophisticated enough to potentially assist with advanced cyberattacks or exploit sensitive information at a scale no human team could match.

After a string of high-profile hacking and security incidents, the NSA’s AI Security Center began testing these models to identify what exactly they are capable of doing to American systems, according to the Washington Sun’s reporting.

The price tag is significantly greater than previously known. And according to the sources, it has led lawmakers to believe that a more comprehensive AI regulatory system could cost the government tens of billions of dollars per year.

Tens of billions. Per year. For AI testing alone.

What Big Tech Wants and What Taxpayers Are Getting Stuck With

President Donald Trump has mostly resisted calls for greater federal oversight of AI, rejecting regulatory proposals from members of Congress and the frontier labs aimed at imposing new safeguards on the models. That resistance reflects sound instincts about government overreach into private technology markets.

But the NSA spending figure complicates that picture in a specific way. Taxpayers are apparently already footing a massive bill to test systems built by some of the wealthiest corporations on earth. Anthropic has lined up computing deals that could cost as much as $517 billion, according to The Information. Some top AI engineers have accepted salary packages in the hundreds of millions of dollars. These companies are not small startups struggling to survive.

And yet the federal government, operating on a classified budget, apparently absorbs billions in testing costs that arguably exist to protect the labs’ products from being weaponized.

Nathan Calvin, general counsel at Encode, an AI advocacy organization, acknowledged the structural problem plainly. “Having in-house AI evaluation capability I think is extremely important and necessary. But it is genuinely expensive,” Calvin said. “You’re competing in bidding with some of the most price-insensitive customers.”

That last line is worth sitting with. The NSA, even with its deep roster of technical talent, competes for computing resources against companies spending at a scale the federal government simply cannot match through normal procurement. The result is a structurally expensive testing operation baked into classified accounts where congressional oversight is limited and public accountability is essentially nonexistent.

Nat Purser, director of US Policy at the AI Verification and Evaluation Research Institute, said that “people often underestimate how much computing power it can take to rigorously test advanced AI systems.” Purser argued the government should keep investing, saying, “If we want the government to be equipped to assess these systems, we need to fund the computing resources and expertise that requires.”

But Purser also floated an idea that deserves more attention than it has gotten. “I think of these tests as public goods, but there are reasonable questions about if taxpayers should foot the bill,” Purser said. “An assessment on frontier developers could be required to help fund these independent audits, including the necessary computing resources.”

In plain terms, he is suggesting the AI companies whose products require this scrutiny should pay for the scrutiny themselves. That is not a radical idea. It is the same logic applied to pharmaceutical drug approvals, where the manufacturer funds the review process through user fees rather than passing the full cost to the public.

The Real Danger Nobody Is Talking About Loudly Enough

Some tech leaders, including Elon Musk, have suggested that the frontier labs should review each other’s models prior to release without government oversight. Google, OpenAI, and Anthropic are reportedly working jointly on a plan to create their own AI safety-focused standards body, according to the Washington Sun’s reporting. But some AI safety experts have rejected this model as effectively allowing the firms to police themselves.

That objection has merit, but the government-run alternative carries its own serious problems that rarely get equal attention.

Classified AI testing at the NSA operates with almost no public visibility. The budget is secret. The specific vulnerabilities being tested for are secret. The results are secret. The American people fund this operation but have no meaningful way to know what their money is buying, what standards the NSA applies, or whether those standards align with any democratically accountable policy goal.

Anthropic CEO Dario Amodei has warned publicly that AI could wipe out half of all entry-level white-collar jobs and push unemployment to 10 to 20 percent within one to five years. That is a warning from inside the industry, not from outside critics. The same Big Tech firms building systems capable of that level of disruption are now quietly relying on the NSA to test their products using taxpayer money while they reinvest their own capital into expanded computing capacity.

And the Left sees exactly where this is heading. If government becomes the central authority on AI safety determinations, the same political machine that spent years using Big Tech platforms to suppress conservative speech on COVID policy, the 2020 election, and January 6 gains a new lever. Classified AI safety assessments become a tool for deciding which AI capabilities get cleared and which get restricted. That is not paranoia. That is the predictable behavior of institutions that have already demonstrated they treat “safety” and “acceptable content” as interchangeable concepts when it suits their political interests.

The Congressional Budget Office estimated that H.R. 9363, the AI Security and Innovation Act, would authorize $20 million for each fiscal year from 2027 through 2032 for a civilian National Institute of Standards and Technology center focused on AI risk measurement, with estimated implementation costs of $80 million over the 2026 through 2031 period. Compare that to the billions the NSA reportedly spends in a single year. The gap between what Congress has debated publicly and what the intelligence community is spending in the dark is extraordinary.

Democrat Senators Mark Warner of Virginia and Brian Schatz of Hawaii recently attempted to force a Senate floor vote on legislation that would require frontier companies like Anthropic and OpenAI to submit their models to NSA review before release. Currently, the Trump administration has set up only an optional regime for testing. Warner and Schatz want it mandatory, with fines of not less than $100,000 per day for companies that fail to comply, according to King and Spalding’s analysis of the bill.

Mandatory pre-release government approval of AI models is a significant power. Combined with classified budgets and no public accountability for what the NSA finds or does with its findings, this is a government surveillance and control apparatus being built around the technology that will define the next generation of the economy.

Trump has been right to resist mandatory federal AI oversight pushed by Democrats in Congress. The pressure to hand unaccountable intelligence agencies the keys to AI approval processes should raise alarms regardless of which party is in power. The NSA’s classified budget is already operating at a scale Congress never formally authorized through open debate. Adding mandatory pre-release review authority on top of that spending is not a safety upgrade. It is a power grab dressed in technical language.

The question of who pays for AI testing is legitimate. Making Big Tech fund independent audits rather than offloading that cost onto classified taxpayer accounts is a reasonable policy conversation worth having. But the larger issue is transparency. Any government operation spending billions annually to evaluate the most consequential technology ever built should operate with far more accountability than the classification system currently allows.

Working families do not get to know what the NSA is testing for. They do not get to know whether the results are shared with the companies whose systems are being evaluated. They do not get to know whether the testing standards reflect national security interests or the ideological preferences of the permanent bureaucracy running the program.

But they get to pay for all of it.

Sources: The Washington Sun, Jeff Stein, “Classified Estimates Show the NSA Is Paying Billions to Test AI Models,” September 24, 2026; King and Spalding analysis of the Secure Artificial Intelligence Development Act of 2026; Congressional Budget Office estimate of H.R. 9363; The Information reporting on Anthropic computing deals.